[Samba] Testing domain group membership

John H Terpstra jht at Samba.Org
Mon May 23 17:20:05 GMT 2005


On Monday 23 May 2005 11:09, Rex Dieter wrote:
> Is there a samba command (using net,wbinfo, or whatever) to allow one to
> test whether a user is a member of a particular (domain) group?
>
> I know that
> $ net user info
> returns the groups that a user is a (direct) member of, but for my
> immediate purposes, that is not sufficient (we're using nested groups).

Suggest you check out chapter 12 of the Samba-HOWTO-Collection.pdf. This 
document can be obtained from:

	http://www.samba.org/samba/docs/Samba-HOWTO-Collection.pdf

If the information in this chapter does not meet your needs please let me know 
as soon as possible. So I can fix it before it goes to print.

- John T.

>
> I also know that
> ntlm_auth has the --require-membership-of=STRING option, but it also
> requires one to have access to the users' password (to be tested) as well.
>
> -- Rex

-- 
John H Terpstra
Samba-Team Member
Phone: +1 (650) 580-8668

Author:
The Official Samba-3 HOWTO & Reference Guide, ISBN: 0131453556
Samba-3 by Example, ISBN: 0131472216
Hardening Linux, ISBN: 0072254971
Other books in production.


More information about the samba mailing list